Unauthenticated XSS Vulnerability in Post and Page Builder Plugin by BoldGrid
CVE-2026-100510
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-100510?
An unauthenticated Cross-Site Scripting (XSS) vulnerability exists in the Post and Page Builder plugin by BoldGrid for versions up to 1.27.14. Attackers can exploit this flaw to inject malicious scripts, potentially compromising the security of user sessions, leading to data theft or unauthorized actions on the affected WordPress site. It's crucial for users to update their plugin to mitigate the risk of exploitation.
Affected Version(s)
Post and Page Builder by BoldGrid <= 1.27.14